# Fetch compliance graph data for a specific profile on a resource Retrieves compliance graph data for a specific profile on a specific resource, showing the pass/fail breakdown for that profile's rules. ## Endpoint `GET /dcapi/scap/compliance/result/profilesGraph/{resourceId}` ## Request ### Request URL `https://{serverurl}/dcapi/scap/compliance/result/profilesGraph/{resourceId}` `{serverurl}`: [OAuth Authentication Endpoint Domain](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html) ### Scope `DesktopCentralCloud.VulnerabilityMgmt.READ` ### Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ### Request Parameters #### Path Parameters | Parameter | Type | Required | Description | |---|---|---|---| | resourceId | string | Mandatory | Computer/resource ID. Fetch from [Get CG Association Details](https://www.manageengine.com/products/desktop-central/help/api/cloud/get-cg-association-details.html) | #### Query Parameters | Parameter | Type | Required | Description | |---|---|---|---| | collectionId | long | Optional | Collection ID | | profileId | long | Optional | Profile/benchmark ID | | profileType | long | Optional | Profile type. 1 = XCCDF, 0 = OVAL | ### Sample Request ```curl curl --request GET \ --url https://appdomains/dcapi/scap/compliance/result/profilesGraph/{resourceId} \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 Response body: `application/json` | Attribute | Type | Description | |---|---|---| | scan | string | Scan status. `SCAN_COMPLETED` or `YET_TO_SCAN` | | result | string | Results summary, e.g., `200/245 Rules Passed` or `NA` | | status | JSON Object | Compliance status breakdown for the profile | ### HTTP Code 401 Response body: `application/json` | Attribute | Type | Description | |---|---|---| | errorCode | long | Unauthorized error code: credentials missing, expired, or invalid | | errorMsg | string | Authentication failure reason | ### HTTP Code 429 Response body: `application/json` | Attribute | Type | Description | |---|---|---| | errorCode | long | Rate limit error code returned when the API call reached threshold | | errorMsg | string | Rate limit exceeded message with retry guidance | ### Possible Response Codes | HTTP Code | |---| | 200 | | 401 | | 429 | ### Sample Response: HTTP 200 Profile graph data after scan completion: ```json { "result": "200/245 Rules Passed", "scan": "SCAN_COMPLETED", "status": { "percentage": "82", "breakdown": { "unscored": 15, "passed": 200, "failed": 25, "error": 5 }, "attention": 25, "totalRules": 245 } } ``` Profile graph data before scan: ```json { "result": "NA", "scan": "YET_TO_SCAN", "status": { "percentage": "NA", "breakdown": { "unscored": 245, "passed": 0, "failed": 0, "error": 0 }, "attention": 0, "totalRules": 245 } } ``` ### Sample Response: HTTP 401 Authentication credentials are missing or invalid: ```json { "errorMessage": "Authentication required", "errorCode": "UNAUTHORIZED" } ``` ### Sample Response: HTTP 429 API call threshold exceeded: ```json { "errorMessage": "Rate limit exceeded. Retry after some time", "errorCode": "TOO_MANY_REQUESTS" } ``` ## API Rate Limit ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.